Feeds

Canada's privacy chief hails Microsoft's Seven Laws of Identity

On surviving the identity Big Bang

The Power of One eBook: Top reasons to choose HP BladeSystem

The Information and Privacy Commissioner of Ontario has published a plan for automated internet privacy that is backed by Microsoft. Dr Ann Cavoukian has called for programmers to embed privacy capabilities in software.

A Microsoft-led project to create an "identity layer" for the internet created Seven Laws of Identity, which Cavoukian has used as the basis for a paper calling for the laws to be embedded in software. The aim of the project is to help computer users to manage their own identity online.

"Just as the internet saw explosive growth as it sprang from the connection of different proprietary networks, an 'identity big bang' is expected to happen once an open, non-proprietary and universal method to connect identity systems and ensure user privacy is developed in accordance with privacy principles," said Cavoukian.

"Microsoft started a global privacy momentum. Already, there is a long and growing list of companies and individuals who now endorse the Seven Laws of Identity and are working towards developing identity systems that conform to them," she said.

Cavoukian argues that the latest generation of internet services, commonly called Web 2.0 and depending in many cases on personalisation, will create a demand for more information about users' identities. Users will need to know whether they can trust a site before handing over information, and the Seven Laws are designed to help users make that decision, said Cavoukian's office.

Microsoft has published its own guidelines on embedding privacy into software. "Privacy concerns are easy to understand in principle, but challenging to address in practice, particularly in the development of software," said Peter Cullen, chief privacy strategist at Microsoft. "Similar guidelines have helped Microsoft's developers better understand and address privacy issues, and we hope that by releasing a public version we can promote an ongoing industry dialogue on protecting privacy through consistent development practices."

The proposals for embedded privacy settings is not unlike the Platform for Privacy Preferences (P3P), a World Wide Web Consortium-developed automatic reader and sender of information about a website's privacy policies. It was launched in 2002.

Couvoukian said that another aim of the Seven Laws is to help users cut down on the degree to which data is shared and centralised.

"In the real world when we present a library card, for example, to check out a book, and present our passport to cross a national border we don’t expect these to be linked together," she said. "Nor is the access card we use to enter our office the same as the transit pass we use to board a bus. In the physical world, different transactions require different identity credentials, but they need not be linked together. It should be no different in the online environment."

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Related links

Dr Cavoukian's white paper (24-page / 271KB PDF)
Microsoft's paper on The Laws of Identity

Designing a Defense for Mobile Applications

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.